top of page
Purple - Blue Gradient

Privacy Policy

Suntoyo Technology Pte Ltd and its subsidiaries and affiliates (hereinafter collectively referred to as “Suntoyo”, "we", "our", "us") value the information you have provided us or permitted us to collect. We strive to protect your privacy while providing you with the best service and experience we can provide. All such personal data in our possession is valued and is collected, used, disclosed and protected in accordance with the Singapore Personal Data Protection Act 2012 ("PDPA"). This Privacy Policy applies to all websites on which this Privacy Policy or a link to this Privacy Policy appears, as well as all our activities to the extent that you have been notified that such activities are subject to this Privacy Policy.


This Privacy Policy is intended to apply to all personal data submitted by you, third parties authorised by you via and its sub-domains, any personal data that we receive from other third parties, and any personal data that we obtain through our website(s), our software and application(s), our application programming interfaces (“APIs”), or our products (hereinafter collectively referred to as the "Platforms").


By using the Platform Services (as defined below), visiting or using any of the Platforms and/or providing us with your personal data, you are deemed to agree to the terms of this Privacy Policy. Please review this Privacy Policy carefully prior to visiting or using any such Services and/or Platforms or otherwise providing any personal data. This Privacy Policy may be updated, revised, varied, or amended from time to time as we deem necessary.


This Privacy Policy was last updated on [insert date.]



Platform Services means services and products (including both hardware and software) developed by us from time-to-time, including: our core point-of-sale (“POS”) system; payment processing services; our application programming interfaces (“APIs”); associated modules provided as part of our POS system; and other mobile application(s) developed as part of the Platform Services (collectively referred to as the “Platform Services”).


What personal data we collect will depend on the nature of your interaction with the Platform Services and our Platforms. While some personal data is collected automatically or through sources outside of Suntoyo, most is collected when you or a person authorized by you uses our Platform Services or our Platforms. A breakdown of the collection is provided in the sections below.


(A) Data we collect about merchants and their personnel

If you are a merchant or prospective customer, we collect data (some of which may constitute personal data) directly from you about yourself and your personnel. We may collect information from you in a variety of contexts, such as when visiting our Platforms, completing one of our online forms, when you provide us such data in the course of using our Platform Services, interacting with us on social media, or corresponding with us. The types of information we obtain in these contexts include:

  • Contact information of the business entity and its personnel who interact with us, such as name, job title, address, telephone number, and email address;

  • Profile information, such as username and password that an individual may establish on one of our Platforms or mobile applications, along with any other information that an individual enters into their account profile;

  • Demographic details, such as date of birth, country of citizenship and/or country of residence;

  • Information about the individuals’ affiliation with a legal entity, such as an individual’s role, and whether he or she is a beneficial owner or authorised signatory;

  • Government-issued identification numbers (to the extent permitted under applicable law), such as NRIC number, FIN number, driver's licence, passport number, or work permit number;

  • Feedback and correspondence, such as information provided when information is request information from us, receive customer support, or otherwise correspond with us, including by interacting with our pages on social networking online sites;

  • Financial account information, such as payment card or bank account details;

  • Information about merchants, such as merchant name, merchant ID and category code, merchant location where a transaction occurred, and information about transactions processed by the merchant, including transaction volume, velocity, amounts, types of goods or services sold, and chargeback ratios;

  • Information related to a merchant’s use of our Platform Services, such as account information, spending thresholds, spending activity and patterns, and information about the transactions we process;

  • Information about a merchant’s personnel and their interaction with our Platform Services, such as clock-in and clock-out time, and additional job-related information depending on what Platform Services are being provided to a merchant; and

  • Marketing information, such as your preferences for receiving marketing communications, merchant surveys, and details about how you engage with our marketing communications.

(B) Personal data we collect when individuals make a payment

If you are a customer of a merchant who uses our Platform Services, in your (or the merchant’s) usage of the Platform and the Platform services (for example, when making payment at a POS system provided by us) we are provided information about the transaction, such as the payment card used, name associated with the payment card, electronic signature, name and location of the merchant at which the transaction occurred, date and time of the transaction, transaction amount, and information about the goods or services purchased in the transaction.

(C) Additional personal data customers of our merchants may provide through the Suntoyo POS system

We may collect additional personal data of you as a customer, depending on the Platform Services being used. Such personal data may include:

  • Your email address or phone number, for example, if you choose to receive an electronic receipt or opt-in to receive marketing communications;

  • Your marketing preferences, such as whether you wish to receive marketing communications or newsletters;

  • Information about your participation in a merchant’s loyalty program, if offered and if you choose to participate; and

  • Other information you choose to enter or authorize the merchant to enter into the Platform, such as your date of birth, interests or preferences, reviews, and feedback.

(D) Personal data we receive from other sources including third parties and publicly available sources

Depending on whether you are a merchant, its personnel, a customer of a merchant, or a visitor to the Platform, we may also collect personal data about you from third parties, including our business partners, data providers, identity verification services, credit bureaus (if applicable) and credit card companies. We may also collect personal data from you that is publicly available, such as when you interact with us through our social media channels.

When individuals interact with our social media channels on those third-party platforms, the third-party’s privacy policy will govern your interactions on the relevant platform. If the third-party platform provides us with information about our social media channels on those platforms or your interactions with them, we will treat that information in accordance with this Privacy Policy.

(E) Personal data we collect automatically through the use of cookies and other tracking technologies

We collect personal data automatically when you visit our Platforms or use our Platform Services. Personal data collected automatically by cookies, web beacons or other similar technologies may include:

  • Information about your device, such as your device type/model, number and device ID (e.g. MAC address);

  • Information about your browser, settings (e.g. language) and operating system;

  • Transactional and purchase information; and

  • Browsing and usage activity, such as the referring domain, what websites/content you have viewed or actions you have taken on a particular website.

Collection of personal data

Wherever possible, we will collect personal data directly from you. We will only collect, use and disclose personal data with your consent, your deemed consent or as may be otherwise permitted under the PDPA or other applicable laws.


In addition to the personal data you provide to us, certain information related to you that is not considered personal data under the PDPA may also be collected. We collect this information to improve our website. Such non-personal data may include information such as your IP address, the internet browser you use, details of your interaction with our website and other types of non-personal data.


Use of cookies

Cookies are small files which require user permission in order to be installed on a computer’s hard drive. Cookies will only start to perform their functions after such permission is granted. By collecting and analysing data on the user’s browsing patterns, cookies allow web applications to respond to the user as an individual by tailoring a web application’s operations to the user’s specific needs and preferences.


Permission for cookies is granted by default in most web browsers. You can however choose to disable this function in your browser’s settings. This may prevent you from taking full advantage of our website.


We may use traffic log cookies to identify which pages are being used. This use is designed to assist us in gathering data on web page traffic. The gathered data is used only for statistical purposes and is removed from our database shortly after.

Overall, the data collected by the cookies is used for the purpose of improving your browsing experience on our website. Cookies do not grant us access to your computer or any information about you outside of your browsing activity on our website.


We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:

  • Where you have consented before the processing;

  • Where we need to perform a contract that we are about to enter or have entered with you;

  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests; and

  • Where we need to comply with a legal or regulatory obligation.

A breakdown of the purposes for collection of your personal data is provided in the sections below


(A) To provide, maintain and support our Platform Services, including:


  • To provide updates, support and training related to the Platform Services;

  • For contracting and agreement purposes;

  • To provide the Platform Services, including processing transactions and payments through the Platform;

  • To deliver electronic receipts to customers of our merchants;

  • To enable our merchants and their personnel to access and use the Platform Services, including information that you have provided as part of using the Platform Services; and

  • To provide online services, including verifying your identity, as well as diagnosing technical and service issues.


(B) To manage our business and for internal operational purposes, including:


  • Analysing the performance of our Platform Services;

  • Workforce development;

  • Creating and developing analytics for the benefit of our business and the business of our merchants;

  • Research purposes, including the development of new products and services;

  • Assessing the effectiveness of our Platform Services; and

  • Improving our Platform Services and Platforms.


(C) To personalise your experience, including:


  • Using transactional data and order histories to provide recommendations when using our Platform Services; and

  • Using analytics and profiling technology to personalise your online experience on our Platforms.


(D) To advertise and market to you, including:


  • Sending you marketing communications, either directly or through a third party, in relation to our existing or new Platform Services that we think might interest you; and

  • Enabling our merchants, either directly or through a third party, to advertise their products and services to you.


(E) For legal, compliance and security-related purposes, including to:


  • Secure and protect our network and systems;

  • Identify and protect against fraud and other crimes;

  • Establish, exercise or defend legal claims;

  • Fulfil our contractual obligations;

  • Monitor and report compliance issues; and

  • Comply with applicable laws, lawful requests and legal processes, such as to respond to requests from government authorities.

We may, for the above purposes, contact you via mail, electronic mail, telephone, SMS, facsimile or other forms of communication through mobile applications. Should you wish to opt-out of our contact list for any reason, please refer to the below paragraph 8 for the relevant procedure.



In the course of providing our services and products to you, we may need to disclose your personal data with external organisations or individuals. The reasons for which we may disclose your personal data are set out under paragraph 3 above. The possible parties we may share your personal data with include:

  • Our merchants and their personnel for the purposes of providing the Platform Services to you, fulfilling your requests and for the other purposes described in this Privacy Policy;

  • Our business partners (including our integration partners) in order to provide, maintain and improve and expand our Platform Services;

  • Our parent, subsidiary, or affiliate companies, agents (if any) for the purposes outlined above;

  • Third parties, to provide, maintain, and improve our Platform Services, including service providers who access information about you to perform services on our behalf, such as hosting and information technology services, payment and payment gateway services, identity verification and fraud prevention services, marketing and advertising services, data analytics, personalisation service, and customer support services; and

  • Third parties in connection with, or during the negotiation of, any merger, sale of company stock or assets, financing, acquisition, divestiture, or dissolution of all or a portion of our business.

  • In addition, we may disclose your personal data if we believe it is necessary to:

  • Protect our rights or property, or the security or integrity of our Platform Services or our Platforms;

  • Enforce the terms of our terms of service or other applicable agreements or policies;

  • Protect us, users of our Platform Services, or the public from harm or potentially prohibited or illegal activities;

  • Investigate, detect, and prevent fraud, security breaches; or

  • Comply with any applicable law, regulation, legal process, or governmental request.

  • In the event that any of the above parties receiving your personal data are located or are operating outside of Singapore, we will take reasonable steps to ensure that the overseas recipient provides a standard of protection to your personal data so transferred that is comparable to the protection under the PDPA.


Our Platforms may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. Please note that these websites and any services that may be accessible through them have their own privacy policies and that Suntoyo does not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services. Please check these policies before you submit any personal data to these websites or use these services.


We implement appropriate administrative, technical, and organisational security measures to protect your personal data against unauthorised access, disclosure, damage or loss. However, even though we have taken reasonable precautions to protect your personal data, we cannot guarantee that the collection, transmission and storage of personal data will always be completely secure.

We have put in place procedures to deal with any suspected personal data breach and will notify you and the Personal Data Protection Commission of Singapore or any applicable regulator of a breach where we are legally required to do so.


We will retain your personal data as long as reasonably necessary to provide the Platform Services, carry out the purposes described in this Privacy Policy or as otherwise required in order to comply with our records retention periods (which reflect the applicable law). We may retain personal data about users of our Platform Services in order to comply with our legal and regulatory obligations or to protect our interests as part of providing the Platform Services.


In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.


Where you have the right to request deletion of your personal data, we will delete your personal data in accordance with and upon receipt of written instructions from you to this effect, unless we are legally required to keep it. If deletion is not possible, we will anonymise your personal data such that re-identification is not possible. If anonymisation is not possible (for example, your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.


Under certain circumstances you have the following rights under data protection laws in relation to your personal data:

(A) Request access to your personal data;

This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

(B) Request correction of your personal data;

This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

(C) Request deletion of your personal data;

This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to delete your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

(D) Object to processing of your personal data;

This enables you to object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

(E) Request transfer or your personal data; and

This enables you to request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

(F) Right to withdraw consent for us to collect, use and/or disclose your personal data.

This enables you to withdraw your consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

To exercise any of your rights above, you must contact our data protection officer at []. Please note that it may take up to [thirty (30) days] after receipt of your request for us to process your request. For details on how to make such request, please contact us.




We reserve the right to amend this Privacy Policy at any time. If material changes are made to this Privacy Policy, we will notify you by updating the date of this Privacy Policy on this page. We may (and, where required by law, will) also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through our Platforms. We encourage you to review this page periodically in order for you to stay notified of any changes.


Your continued use and/or acceptance of the Platform Services or Platforms after any changes to this Privacy Policy constitutes your consent to any such changes, to the extent such consent is not otherwise provided.



If you have comments or questions about this Privacy Policy, or wish to submit a request mentioned in paragraph 8 above, please contact our data protection officer at:


Email address:            


Telephone number:          +65 6553 3855




Nothing in this Privacy Policy shall limit your rights under the Personal Data Protection Act (2012) of Singapore, or any other data protection or privacy related law that is applicable to you. This Privacy Policy shall be governed by the laws of the Republic of Singapore and you agree to submit to the exclusive jurisdiction of the Singapore courts.

How can we assist you?

bottom of page